Contact Zero

CVE-2026-78501

microsoft 365 copilot chat

score 40HIGH 7.4watchlist: microsoft

Summary

Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.

Published 2026-09-17 · first seen here 2026-10-10

Hunt & detect

Threat hunt brief, Sigma rule and Splunk / Sentinel / CrowdStrike queries are not available for this item yet.

Coverage

References